CVE-2000-1207

userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).
Configurations

Configuration 1 (hide)

cpe:2.3:o:redhat:linux:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:34

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=97034397026473&w=2 - () http://marc.info/?l=bugtraq&m=97034397026473&w=2 -
References () http://marc.info/?l=bugtraq&m=97063854808796&w=2 - () http://marc.info/?l=bugtraq&m=97063854808796&w=2 -
References () http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-059.php3 - Vendor Advisory () http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-059.php3 - Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2000-075.html - Patch, Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2000-075.html - Patch, Vendor Advisory

Information

Published : 2000-09-30 04:00

Updated : 2024-11-20 23:34


NVD link : CVE-2000-1207

Mitre link : CVE-2000-1207

CVE.ORG link : CVE-2000-1207


JSON object : View

Products Affected

redhat

  • linux